logo

New Cyberthreat 'Boolka' Deploying BMANAGER Trojan via SQLi Attacks

ID: 27e999c0-5c77-5aaa-9bca-a099a350bf31

STIX ID: report--27e999c0-5c77-5aaa-9bca-a099a350bf31

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-25

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

**Boolka** is an opportunistic criminal actor that has been exploiting SQL injection vulnerabilities since at least 2022 to inject malicious JavaScript into websites which exfiltrates user inputs and redirects victims to a fake loader that delivers a downloader for the modular trojan **BMANAGER**; BMANAGER deploys modules (BMBACKUP, BMHOOK, BMLOG, BMREADER) to harvest files, record focused applications and keystrokes, export stolen data, and maintain persistence (noted indicators include the C2 domain boolka.tk and a hard-coded local DB path C:\Users\{user}\AppData\Local\Temp\coollog.db).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.